well another thing i was going to ask is it on a shared account or a private server... cause i know there is a few exploits out right now on linux servers that will get you in sql pretty quick too esp on a shared server... do you have any other admins who would be messing around ? i would check out all the logs from admincp see what you see in there... one other thing you could do also is put a htaccess on admincp also...
|